Medium - CVE-2024-5667 - Multiple plugins for WordPress are vulnerable...
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Featherlight.js JavaScript library (versions 1.7.13 to 1.7.14) in various versions due to...
Medium - CVE-2025-0954 - The WP Online Contract plugin for WordPress is...
The WP Online Contract plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the json_import() and json_export() functions in all versions up to, and...
High - CVE-2025-0956 - The WooCommerce Recover Abandoned Cart plugin...
The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 24.3.0 via deserialization of untrusted input from the...
Critical - CVE-2025-1515 - The WP Real Estate Manager plugin for WordPress...
The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.8. This is due to insufficient identity verification on the LinkedIn...
NA - CVE-2025-25015 - Prototype pollution in Kibana leads to...
Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by...
Medium - CVE-2024-11153 - The Content Control – The Ultimate Content...
The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Critical - CVE-2024-11951 - The Homey Login Register plugin for WordPress...
The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.0. This is due to the plugin allowing users who are registering new...
Critical - CVE-2024-12281 - The Homey theme for WordPress is vulnerable to...
The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is due to the plugin allowing users who are registering new accounts to set...
Medium - CVE-2024-12650 - An attacker with low privileges can manipulate...
An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area. This could lead to a crash of the application but it does not...
Medium - CVE-2024-13423 - The Sparkling theme for WordPress is vulnerable...
The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and...